Art. 20
Management body
The governing organ of an entity, which must approve cybersecurity risk-management measures, oversee their implementation and follow training.
Article 20 is what moved NIS2 into boardrooms. Member states must ensure management bodies can be held liable for infringements, and article 32(6) allows a competent authority to temporarily prohibit a named individual from exercising managerial functions in an essential entity.
Related terms
- Essential entity · Art. 3(1)
- Important entity · Art. 3(2)
- Significant incident · Art. 23(3)
- Early warning · Art. 23(4)(a)
- Size-cap rule · Art. 2(1)
- CSIRT · Art. 10